Security Advisory

CVE-2024-6611

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-07-09 14:25:59
Last updated 2025-10-30 16:15:03
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.